The Gluster file system through versions 4.1.4 and 3.12 is vulnerable to a heap-based buffer overflow in the __server_getspec function via the gf_getspec_req RPC message. A remote authenticated attacker could exploit this to cause a denial of service or other potential unspecified impact.
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
Name | Vendor | Start Version | End Version |
---|---|---|---|
Gluster_storage | Redhat | 3.0.0 (including) | 3.1.2 (including) |
Gluster_storage | Redhat | 4.1.0 (including) | 4.1.4 (including) |
Native Client for RHEL 6 for Red Hat Storage | RedHat | glusterfs-0:3.12.2-25.el6 | * |
Native Client for RHEL 7 for Red Hat Storage | RedHat | glusterfs-0:3.12.2-25.el7 | * |
Red Hat Gluster Storage 3.4 for RHEL 6 | RedHat | glusterfs-0:3.12.2-25.el6rhs | * |
Red Hat Gluster Storage 3.4 for RHEL 6 | RedHat | redhat-storage-server-0:3.4.1.0-1.el6rhs | * |
Red Hat Gluster Storage 3.4 for RHEL 7 | RedHat | glusterfs-0:3.12.2-25.el7rhgs | * |
Red Hat Gluster Storage 3.4 for RHEL 7 | RedHat | redhat-storage-server-0:3.4.1.0-1.el7rhgs | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | glusterfs-0:3.12.2-25.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | imgbased-0:1.0.29-1.el7ev | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-release-virtualization-host-0:4.2-7.3.el7 | * |
Red Hat Virtualization 4 for Red Hat Enterprise Linux 7 | RedHat | redhat-virtualization-host-0:4.2-20181026.0.el7_6 | * |
Glusterfs | Ubuntu | bionic | * |
Glusterfs | Ubuntu | cosmic | * |
Glusterfs | Ubuntu | esm-apps/bionic | * |
Glusterfs | Ubuntu | esm-apps/xenial | * |
Glusterfs | Ubuntu | trusty | * |
Glusterfs | Ubuntu | trusty/esm | * |
Glusterfs | Ubuntu | xenial | * |